CVE Database

53435+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2024-2210
6.4 MEDIUM

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.4.1 via the …

Mar 27, 2024
CVE-2024-2203
6.4 MEDIUM

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.4.1 via the …

Mar 27, 2024
CVE-2024-2139
6.4 MEDIUM

The Master Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Pricing Table widget in all versions up to, and …

Mar 27, 2024
CVE-2024-25580
6.2 MEDIUM

An issue was discovered in gui/util/qktxhandler.cpp in Qt before 5.15.17, 6.x before 6.2.12, 6.3.x through 6.5.x before 6.5.5, and 6.6.x before 6.6.2. A buffer overflow …

Mar 27, 2024
CVE-2024-25394
4.3 MEDIUM

A buffer overflow occurs in utilities/ymodem/ry_sy.c in RT-Thread through 5.0.2 because of an incorrect sprintf call or a missing '\0' character.

Mar 27, 2024
CVE-2024-25392
5.9 MEDIUM

An out-of-bounds access occurs in utilities/var_export/var_export.c in RT-Thread through 5.0.2.

Mar 27, 2024
CVE-2024-1532
6.8 MEDIUM

A vulnerability exists in the stb-language file handling that affects the RTU500 series product versions listed below. A malicious actor could enforce diagnostic texts being …

Mar 27, 2024
CVE-2024-2244
5.3 MEDIUM

REST service authentication anomaly with “valid username/no password” credential combination for batch job processing resulting in successful service invocation. The anomaly doesn’t exist with other …

Mar 27, 2024
CVE-2024-2938
6.3 MEDIUM

A vulnerability was found in Campcodes Online Examination System 1.0. It has been rated as critical. This issue affects some unknown processing of the file …

Mar 27, 2024
CVE-2024-2934
6.3 MEDIUM

A vulnerability classified as critical was found in SourceCodester Todo List in Kanban Board 1.0. Affected by this vulnerability is an unknown functionality of the …

Mar 27, 2024
CVE-2024-2932
6.3 MEDIUM

A vulnerability classified as critical has been found in SourceCodester Online Chatting System 1.0. Affected is an unknown function of the file admin/update_room.php. The manipulation …

Mar 27, 2024
CVE-2024-2206
6.5 MEDIUM

An SSRF vulnerability exists in the gradio-app/gradio due to insufficient validation of user-supplied URLs in the `/proxy` route. Attackers can exploit this vulnerability by manipulating …

Mar 27, 2024
CVE-2024-2209
6.3 MEDIUM

A user with administrative privileges can create a compromised dll file of the same name as the original dll within the HP printer’s Firmware Update …

Mar 27, 2024
CVE-2024-2917
5.4 MEDIUM

A vulnerability was found in Campcodes House Rental Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality …

Mar 26, 2024
CVE-2024-25138
6.5 MEDIUM

In AutomationDirect C-MORE EA9 HMI, credentials used by the platform are stored as plain text on the device.

Mar 26, 2024
CVE-2024-25137
4.3 MEDIUM

In AutomationDirect C-MORE EA9 HMI there is a program that copies a buffer of a size controlled by the user into a limited sized buffer …

Mar 26, 2024
CVE-2024-2911
4.3 MEDIUM

A vulnerability, which was classified as problematic, was found in Tianjin PubliCMS 4.0.202302.e. This affects an unknown part. The manipulation leads to cross-site request forgery. …

Mar 26, 2024
CVE-2024-2910
6.3 MEDIUM

A vulnerability, which was classified as critical, has been found in Ruijie RG-EG350 up to 20240318. Affected by this issue is the function vpnAction of …

Mar 26, 2024
CVE-2024-26303
4.9 MEDIUM

Authenticated Denial of Service Vulnerability in ArubaOS-Switch SSH Daemon

Mar 26, 2024
CVE-2023-27630
5.3 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in PeepSo Community by PeepSo.This issue affects Community by PeepSo: from n/a through 6.0.9.0.

Mar 26, 2024
CVE-2023-25965
5.9 MEDIUM

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in mbbhatti Upload Resume.This issue affects Upload Resume: from n/a through 1.2.0.

Mar 26, 2024
CVE-2024-2897
6.3 MEDIUM

A vulnerability classified as critical has been found in Tenda AC7 15.03.06.44. Affected is the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the …

Mar 26, 2024
CVE-2024-22436
6.5 MEDIUM

A security vulnerability in HPE IceWall Agent products could be exploited remotely to cause a denial of service.

Mar 26, 2024
CVE-2024-2951
4.3 MEDIUM

Cross-Site Request Forgery (CSRF) vulnerability in Metagauss RegistrationMagic.This issue affects RegistrationMagic: from n/a through 5.3.0.0.

Mar 26, 2024
CVE-2024-26649
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Fix the null pointer when load rlc firmware If the RLC firmware is invalid …

Mar 26, 2024
CVE-2024-26648
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix variable deferencing before NULL check in edp_setup_replay() In edp_setup_replay(), 'struct dc *dc' & …

Mar 26, 2024
CVE-2024-26647
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix late derefrence 'dsc' check in 'link_set_dsc_pps_packet()' In link_set_dsc_pps_packet(), 'struct display_stream_compressor *dsc' was dereferenced …

Mar 26, 2024
CVE-2024-26646
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: thermal: intel: hfi: Add syscore callbacks for system-wide PM The kernel allocates a memory buffer …

Mar 26, 2024
CVE-2024-1313
6.5 MEDIUM

It is possible for a user in a different organization from the owner of a snapshot to bypass authorization and delete a snapshot by issuing …

Mar 26, 2024
CVE-2023-52627
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: iio: adc: ad7091r: Allow users to configure device events AD7091R-5 devices are supported by the …

Mar 26, 2024
CVE-2023-52625
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Refactor DMCUB enter/exit idle interface [Why] We can hang in place trying to send …

Mar 26, 2024
CVE-2023-52623
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: SUNRPC: Fix a suspicious RCU usage warning I received the following warning while running cthon …

Mar 26, 2024
CVE-2023-52622
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: ext4: avoid online resizing failures due to oversized flex bg When we online resize an …

Mar 26, 2024
CVE-2024-29735
5.3 MEDIUM

Improper Preservation of Permissions vulnerability in Apache Airflow.This issue affects Apache Airflow from 2.8.2 through 2.8.3. Airflow's local file task handler in Airflow incorrectly set …

Mar 26, 2024
CVE-2024-29833
5.4 MEDIUM

The image upload component allows SVG files and the regular expression used to remove script tags can be bypassed by using a Cross Site Scripting …

Mar 26, 2024
CVE-2024-29832
6.1 MEDIUM

The current_url parameter of the AJAX call to the GalleryBox action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of the current_url …

Mar 26, 2024
CVE-2024-29810
5.4 MEDIUM

The thumb_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of the thumb_url …

Mar 26, 2024
CVE-2024-29809
5.4 MEDIUM

The image_url parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of the image_url …

Mar 26, 2024
CVE-2024-29808
5.4 MEDIUM

The image_id parameter of the AJAX call to the editimage_bwg action of admin-ajax.php is vulnerable to reflected Cross Site Scripting. The value of the image_id …

Mar 26, 2024
CVE-2024-26645
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: tracing: Ensure visibility when inserting an element into tracing_map Running the following two commands in …

Mar 26, 2024
CVE-2024-26644
5.5 MEDIUM

In the Linux kernel, the following vulnerability has been resolved: btrfs: don't abort filesystem when attempting to snapshot deleted subvolume If the source file descriptor …

Mar 26, 2024
CVE-2024-25958
6.7 MEDIUM

Dell Grab for Windows, versions up to and including 5.0.4, contain Weak Application Folder Permissions vulnerability. A local authenticated attacker could potentially exploit this vulnerability, …

Mar 26, 2024
CVE-2024-25957
4.8 MEDIUM

Dell Grab for Windows, versions 5.0.4 and below, contains a cleartext storage of sensitive information vulnerability in its appsync module. An authenticated local attacker could …

Mar 26, 2024
CVE-2024-25956
5.5 MEDIUM

Dell Grab for Windows, versions 5.0.4 and below, contains an improper file permissions vulnerability. A locally authenticated attacker could potentially exploit this vulnerability, leading to …

Mar 26, 2024
CVE-2024-21920
4.4 MEDIUM

A memory buffer vulnerability in Rockwell Automation Arena Simulation could potentially let a threat actor read beyond the intended memory boundaries. This could reveal sensitive …

Mar 26, 2024
CVE-2024-29197
6.5 MEDIUM

Pimcore is an Open Source Data & Experience Management Platform. Any call with the query argument `?pimcore_preview=true` allows to view unpublished sites. In previous versions …

Mar 26, 2024
CVE-2024-22356
4.9 MEDIUM

IBM App Connect Enterprise 11.0.0.1 through 11.0.0.23, 12.0.1.0 through 12.0.9.0 and IBM Integration Bus for z/OS 10.1 through 10.1.0.2store potentially sensitive information in log or …

Mar 26, 2024
CVE-2024-29883
4.9 MEDIUM

CreateWiki is Miraheze's MediaWiki extension for requesting & creating wikis. Suppression of wiki requests does not work as intended, and always restricts visibility to those …

Mar 26, 2024
CVE-2024-29881
4.3 MEDIUM

TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content loading and content inserting code. A SVG …

Mar 26, 2024
CVE-2024-29203
4.3 MEDIUM

TinyMCE is an open source rich text editor. A cross-site scripting (XSS) vulnerability was discovered in TinyMCE’s content insertion code. This allowed `iframe` elements containing …

Mar 26, 2024

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.